There has been talk on the HLDS (Half-Life Dedicated Server) mailing lists that game servers running the popular server administration tool Adminmod are vulnerable to attacks through an exploit found recently. There is a slight possibility that someone with the knowledge of this exploit can gain remote access to the server. The current suggestion to fix the exploit is to disable the rcon password. Just change the line to look like the following:
» rcon_password ""
There are other reports that server side addons such as ClanMod and StatsMe are also vulnerable to the exploit. Please don't ask how use this exploit, because neither I nor anyone else will tell you. Please also refrain from posting any link with the exploit in the comments.
I have spoken to people who work closely with these programs and they assure me all necessary steps are being taken to resolve these issues. AdminMod currently is working on a beta dll to fix this issue, but has yet to release it for public use.
Thanks to everyone who submitted this, and thanks to Ritchey007 for helping out on this post (most of this was his you know).
» rcon_password ""
There are other reports that server side addons such as ClanMod and StatsMe are also vulnerable to the exploit. Please don't ask how use this exploit, because neither I nor anyone else will tell you. Please also refrain from posting any link with the exploit in the comments.
I have spoken to people who work closely with these programs and they assure me all necessary steps are being taken to resolve these issues. AdminMod currently is working on a beta dll to fix this issue, but has yet to release it for public use.
Thanks to everyone who submitted this, and thanks to Ritchey007 for helping out on this post (most of this was his you know).
Comment